You can enable auditing of logon events in Local Security Policy or the
appropriate container level Group Policy if that is where you are managing
auditing policy. Windows 2000 will show a Terminal Server logon as a type 2
local interactive logon while Windows XP Pro and Windows 2003 will show it
as a type 10 remote logon. The links below may help. --- Steve